Tech Support : support@biometrica.com

CISO / IT SECURITY

The Architecture Brief Your OT Review Has Been Waiting For.

TSA SD 1580/82-2022-01C extends cybersecurity expectations to OT and now classifies Positive Train Control as a Critical Cyber System. RTIS/RVIS sensors are one-way outbound transmitters — one ~30KB cropped JPEG per entry event, no return channel, no X-LST or UMbRA data on the device. A compromised sensor cannot expose what it does not hold.

RTIS RVIS Platform Architecture SOC 2
One-way
Outbound Sensor

No return channel. No commands. No watchlist or identity data flowing back to the device.

Zero
On-Device Sensitive Data

No X-LST entries. No UMbRA records. No biometric templates. Sensor compromise cannot expose what is not there.

~30KB
Per-Event Payload

One cropped JPEG, outbound. The lowest possible OT risk classification — non-sensitive, low-bandwidth, outbound-only.

SOC 2
Compliance Posture

Type II SOC 2 with documented data-flow, penetration test summary, and DPA available on request.

Most Biometric Sensors Fail OT Security Review. RTIS/RVIS Is Designed to Pass.

You are the most common blocker in the freight rail security sale — and that is the right thing for you to be. Your job is to keep the OT network defensible under TSA SD 1580/82-2022-01C and the broader Surface Transportation directive series. Most biometric sensors fail OT review at first contact: they hold watchlist entries on the device, they hold biometric templates on the device, they require a two-way API connection to a vendor cloud, and the vendor classification at OT review is *sensitive data endpoint on the operational network* — which is exactly the classification the directive was written to constrain. The Safience sensor architecture is built to fail none of those tests. It is one-way outbound. It holds no sensitive data. It transmits one ~30KB cropped JPEG per entry event. It does not receive watchlist data, identity records, or any return channel. Every match happens at the Safience platform tier, not on the device. A compromised sensor cannot expose your X-LST. The OT risk classification falls into the lowest category your framework allows. We provide a two-page data-flow diagram, a SOC 2 Type II report, a penetration-test summary, and a DPA before your security architecture review begins.

  1. The On-Device Sensitive Data Gap

    Most biometric sensors hold the watchlist on the device for "edge matching." That design makes the device a sensitive data endpoint by definition. Under TSA SD 1580/82, that classification triggers an extended OT review and typically fails it. RTIS/RVIS sensors hold no watchlist, no biometric templates, and no identity data — matching is platform-level.

  2. The Two-Way API Gap

    Most biometric vendors require a two-way API connection — sensor to vendor cloud and back — for enrollment, list updates, and synchronization. That API surface is the highest-consequence breach scenario. RTIS/RVIS has no return channel. The sensor is a one-way outbound transmitter. There is no command path from the platform to the device.

  3. The Vendor Documentation Gap

    Most vendors hand your team marketing material and ask for an OT review to clear it. Safience hands your team a two-page data-flow diagram, a SOC 2 Type II report, a penetration-test summary, and a DPA — before the review begins.

  4. The Encrypted Identity Data on OT Gap

    Most "edge biometric" vendors point to encryption on the device as defense in depth. Encrypted sensitive data on an OT network is still sensitive data on an OT network — the directive does not exempt encrypted data. RTIS/RVIS removes the data entirely, not just the readable form of it.

Your OT Architecture Review of RTIS/RVIS: Step by Step

Most CISOs need three documents and one architecture call to clear RTIS/RVIS. Here is the path.

  1. Read the data-flow brief

    We send a two-page architecture diagram showing: sensor capture → one-way outbound transmission (~30KB JPEG per event) → platform matching → RAC adjudication → carrier notification. No return channel. No on-device sensitive data.

  2. Review SOC 2 and pentest evidence

    We send the current SOC 2 Type II report and the most recent penetration-test summary. Your team confirms the control environment meets your vendor security threshold.

  3. Sign the DPA

    We send a DPA template that establishes the carrier as data controller for X-LST and Safience as the platform-tier processor. No new data controller relationship is created on the carrier side.

  4. Classify the sensor under SD 1580/82

    Your OT team classifies the sensor in your existing framework. The expected classification under the directive’s risk framework: outbound-only, non-sensitive, low-bandwidth — the lowest available tier.

  5. Approve the deployment

    With the architecture brief, SOC 2, pentest summary, and DPA on file, the sensor clears review on a single pass. Pilot deployment goes live in days; OT cutover is not required.

Typical Biometric Sensor vs. Safience Sensor Architecture

Capability Typical Biometric Sensor Safience RTIS/RVIS Sensor
Direction of traffic Two-way API One-way outbound only
Watchlist on device Yes (for "edge matching") No — platform-level only
Biometric template on device Stored Not stored; instant non-match deletion
Return channel from vendor Required for enrollment/sync None
Per-event payload Continuous video stream or large image One ~30KB cropped JPEG
OT classification under SD 1580/82 Sensitive data endpoint Outbound-only, non-sensitive, low-bandwidth
Vendor documentation provided up front Marketing material Data-flow brief, SOC 2 Type II, pentest summary, DPA
Encrypted on-device data "Defense in depth" No on-device sensitive data to encrypt
Sensor compromise consequence X-LST and identity data exposure Cannot expose what is not on the device

Products for the CISO

The CISO sale is the architecture sale. RTIS/RVIS sensor design is the whole product story; X-LST, UMbRA, eMotive, RAC, and QAPLA all live above the OT boundary.

RTIS / RVIS Sensor Architecture

One-way outbound. ~30KB per event. No on-device sensitive data. No two-way API surface. No edge watchlist.

Platform-Level Matching

All X-LST adjudication and UMbRA comparison happens in the Safience platform tier, not on the carrier's OT network.

RAC Adjudication

Human verification at aankh.biometrica.com before any carrier notification. Architecturally required, not procedural.

Documentation Pack

Data-flow brief, SOC 2 Type II report, penetration-test summary, DPA. Ready before review begins.

Get the Architecture Brief Before Procurement Reaches You.

Schedule a 30-minute architecture call with our security engineering team. You will leave with the two-page data-flow diagram, the SOC 2 Type II report, the penetration-test summary, and the DPA — everything you need to clear the OT security review on the first pass.